#1 (permalink)  
Old 06-26-2009, 12:46 PM
Registered User
 
Join Date: Apr 2005
Posts: 81
Brook is on a distinguished road
CSF question re banned IP addresses.

We have installed CSF (Configserver Security Firewall) on our server (as a cpanel plug-in) and it's been sending me some emails about some banned IP addresses:

Quote:
Banned the following ip addresses on Wed Jun 24 10:03:01 BST 2009

1.2.3.4.5.6(ip) with 230 connections
What does this actually mean? Is it definitely an attack? 230 open connections? Is it the same as hits?

It's banned about 8 IP's and interestingly they come from an education establishment's ISP and another two ISPs that all resolve to the same geographical area! Which is what makes me think this is a calculated attack.

Also the odd thing is, even tho it's banned these IPs - it keeps sending me an email with them saying it's banned them again... are they just temporarily banned?

Thanks in advance!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 06-26-2009, 06:33 PM
Infopro's Avatar
Forum Moderator
 
Join Date: May 2003
Location: Pennsylvania
Posts: 3,498
Infopro is on a distinguished road
Lightbulb

You'll have more luck over at the CSF forums for questions like this.
ConfigServer Scripts Forum - Powered by vBulletin Reading the manual is always a good idea too.
http://www.configserver.com/free/csf/readme.txt

You can set it to the number of connection(s) tracking you like, how to block temp or perm, along with lots more. Just needs to be looked at a few hundred times and tweaked as you go for your own system.

If you're in a hurry, open CSF, click Firewall Security level, click high. Then save. Good solid starting point that you can tweak later to your own tastes.

GL
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 06-26-2009, 07:56 PM
Registered User
 
Join Date: Jul 2005
Location: New Jersey, USA
Posts: 385
PlatinumServerM is on a distinguished road
The subject and headers of that email should provide more details on why it was banned. You can also check the logs and the csf deny file.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 07-02-2009, 01:31 PM
Registered User
 
Join Date: Apr 2005
Posts: 81
Brook is on a distinguished road
Thanks for the replies. I've looked at the readme file, but it doesn't explain the connections. Also posted on the CSF forum, but no answer.

Anyone here know what these connections actually are?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Am I banned? parthaguha cPanel Newbies 1 11-20-2007 07:19 AM
csf question salvatore333 cPanel and WHM Discussions 1 05-29-2007 06:29 PM
CSF firewall - "Manually denied" in the csf.deny file? jols cPanel and WHM Discussions 1 04-05-2007 08:10 AM
csf Ip adding question. Luciel cPanel and WHM Discussions 6 01-22-2007 06:33 PM
CSF Install Question - before starting superiorhost cPanel and WHM Discussions 0 12-11-2006 03:00 PM


All times are GMT -5. The time now is 07:31 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc